Search
πŸ›‘οΈ

CSRF

β€’
Cross Site Request Forgery
β€’
둜그인된 μ‚¬μš©μžμ˜ κΆŒν•œμ„ μ΄μš©ν•΄ μ›ν•˜μ§€ μ•ŠλŠ” μš”μ²­μ„ λ³΄λ‚΄κ²Œ ν•˜λŠ” 곡격

Example

<img src="https://bank.com/transfer?money=1000000">
JavaScript
볡사
μžλ™ μš”μ²­ λ°œμƒ β†’ μ†‘κΈˆλ¨

νŠΉμ§•

β€’
μ‚¬μš©μžλŠ” 정상 둜그인 μƒνƒœ
β€’
μ„œλ²„λŠ” 정상 μ‚¬μš©μž μš”μ²­μœΌλ‘œ 착각

λŒ€μ‘

β€’
CSRF Token
β€’
SameSite Cookie
β€’
Referer/Origin 검증